jump to content

Okta SCIM

Configure Native SCIM 2.0 provisioning in Okta so that platform accounts are created, updated and disabled automatically as assignments change.

Show as Markdown

This guide guides you through setting the native SCIM provisioning from Okta to automatically sync users on the platform.

  • Okta administrator access
  • the platform organization administrator access
  • An Octa plan that supports Provisioning SCIM (Octa Life Cycle Management)

In native mode, Okta pushes user changes to the real-time SCIM 2.0 endpoint of the platform. When you assign users or groups to the platform application in Okta, it:

  • Creates Platform accounts for newly allocated users
  • Updates user attributes when changing to Okta
  • Deactivates Platform accounts when users are not assigned or deactivated
  • Deletes Platform accounts when users are permanently removed (if they are configured)

Mapped Attributes

Title: Mapped Attributes
Okta User Profile Field SCIM Attribute Notes
userName userName Required, unique
displayName displayName
givenName name.givenName
familyName name.familyName
nickName nickName
active active
email emails[type eq "work"].value Multi-valued
primaryPhone phoneNumbers[type eq "work"].value Multi-valued
title title
userType userType
preferredLanguage preferredLanguage
locale locale
timezone timezone
profileUrl profileUrl

Enterprise User Extension attributes:

Okta User Profile Field SCIM Attribute
employeeNumber enterprise:employeeNumber
organization enterprise:organization
department enterprise:department
division enterprise:division
costCenter enterprise:costCenter
manager enterprise:manager.value

Step 1: Generate SCIM Credentials in the platform

Step 1: Generate SCIM Credentials in the platform
  1. Log in to the platform as an organization administrator

  2. Go to Organization Settings > Authentication > Auto-Provisioning

  3. Click Add Connector and select SCIM

  4. Copy the SCIM Endpoint URL and Bearer Token

Step 2: Create a SCIM Application in Okta

Step 2: Create a SCIM Application in Okta
  1. Sign up to you. Okta Admin Console

  2. Go to Applications > Applications

  3. Click Browse App Catalog

  4. Search for SCIM 2.0 Test App (Header Auth) and select it

  5. Click Add Integration

  6. Enter the following:

    Field Value
    Application label Probo
  7. Click Next, then Done

  1. In the platform application, go to Provisioning tab

  2. Click Configure API Integration

  3. Check Enable API Integration

  4. Enter the following:

    Field Value
    SCIM 2.0 Base URL The SCIM endpoint URL (e.g. https://your-probo-domain.com/api/connect/v1/scim/2.0)
    OAuth Bearer Token The Token of the Carrier in Step 1
  5. Click Test API Credentials to check Okta can reach the SCIM platform

  6. Click Save

Step 4: Enable Provisioning Actions

Step 4: Enable Provisioning Actions
  1. In the Provisioning tab, click To App in the left sidebar

  2. Click Edit

  3. Enable the following provisioning actions:

    Action Setting
    Create Users ☑️ Enabled
    Update User Attributes ☑️ Enabled
    Deactivate Users ☑️ Enabled
  4. Click Save

Step 5: Configure Attribute Mappings

Step 5: Configure Attribute Mappings

Default attribute mappings work for most settings. To review or customize them:

  1. In the Provisioning tab, scroll to Attribute Mappings
  2. Mapping review – Okta user profile attributes of the default map for SCIM attributes supported by the platform
  3. Adjust maps if necessary (e.g. maps employeeNumber to urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:employeeNumber)
  4. Click Save

Step 6: Assign Users and Groups

Step 6: Assign Users and Groups
  1. In the platform application, go to Assignments tab
  2. Click Assign > Assign to People or Assign to Groups
  3. Select the users or groups you want to provide to the platform
  4. Click Assign, then Save and Go Back
  5. Click Done

Only assigned users (or members of assigned groups) will be provided. This gives you fine control over who receives a platform account.

Membership roles of the platform are allocated to People or mapped with SAML Role Attribute. SCIM creates people as Employee The job title (title) and user type (userType) are synchronized as the profile context for access assessments, not as a member role.

  1. In Okta, go to the platform app > Provisioning tab > To App to check provisioning status
  2. Go to Reports > System Log and filter by application to see delivery events
  3. On the platform, go to People to verify users have been provisioned
  4. Check Organization Settings > Authentication > Auto-Provisioning > Event Log for detailed SCIM events
  • CauseThe SCIM endpoint URL or carrier token is incorrect or a firewall blocks the connection
  • SolutionCheck the endpoint URL that includes the entire route (which ends in /scim/2.0). Re-generate the carrier token in the platform if necessary. Make sure your network allows HTTPS output from Okta to your platform instance.
  • CauseUsers or groups are not assigned to the app or provision actions are not enabled
  • Solution: Check whether users are assigned to the Assignments The camp and that. Create Users is enabled under Provisioning > To App
  • Cause: Attribute mapping conflicts or missing required attributes
  • Solution: Check the System Log In Okta for specific error messages. Make sure that userName is mapped to a single value, which is not empty (usually the user's email)

Users Not Deactivated After Removal

“Users Not Deactivated After Removal”
  • Cause: Octa may continue to process the modification or Deactivate Users is not enabled
  • Solution: Verify that Deactivate Users is enabled under Provisioning > To AppCheck the system log for the deprovisioning event. For immediate effect, manually trigger a push by clicking on Push Now in the application’s provisioning settings.
  • Cause: userName in Okta does not match an existing platform user email
  • Solution: Make sure that the attribute mapped at userName matches the email format used on the platform.

For the best experience, combine SCIM provisioning with SAML SSO:

  1. SCIM provisioning user life cycle management – automatic creation and deactivation of accounts
  2. SAML SSO deals with authentication – users log in with their Okta credentials

This means that users automatically get platform accounts when they join your organization and lose access when they leave, without the need for manual account management.

Ultima actualizare: